Method for securely operating a software component
Abstract
A method for updating a software component is provided, having the steps of: retrieving deployment information for the software component, wherein the deployment information includes information on program parts of the software component and the runtime configuration thereof; checking whether at least one program part has a flaw and identifying the program part; determining a runtime limitation for the program part which has been identified as having a flaw; adding runtime limitation information to the deployment information for the software component; and carrying out the deployment of the software component on the basis of the deployment information, wherein upon being ran, the software component is subject to the runtime limitation according to the runtime limitation information. Analyzing and temporarily adapting runtime configuration information of a deployment configuration for correcting flaws in software components to be updated simplifies the handling of zero-day exploit vulnerabilities.
Claims
exact text as granted — not AI-modified1 . A method for securely operating a software component, the method comprising:
retrieving deployment information for the software component, wherein the deployment information includes information about program components of the software component and a runtime configuration thereof; checking whether at least one program component has a vulnerability and identifying the at least one program component; determining a runtime restriction for the at least one program component identified as having a vulnerability; inserting runtime restriction information into the deployment information for the software component; and implementing a deployment of the software component on a basis of the deployment information, wherein on being executed, the software component is subject to the runtime restriction in accordance with the runtime restriction information.
2 . The method as claimed in claim 1 ,
wherein the software component is implemented as an instance of a software container and an associated software container image comprises package information, binaries, libraries and configuration data as program components.
3 . The method as claimed in claim 2 ,
wherein the deployment comprises a creation of a modified software container image for the software component in accordance with the deployment information supplemented by the runtime restriction.
4 . The method as claimed in claim 3 ,
wherein before deployment, a functional test of the modified software container image is carried out in a secure processing environment.
5 . The method as claimed in claim 1 ,
wherein the software component is deployed in a runtime environment.
6 . The method as claimed in claim 1 ,
wherein the deployment information references one or more software container image(s).
7 . The method as claimed in claim 1 ,
wherein the inserting the runtime restriction information is carried out via a merge request for a build pipeline that causes the software component to be updated.
8 . The method as claimed in claim 1 ,
wherein the checking comprises a search of the deployment information and/or a scan of the software container image. the checking
9 . The method as claimed in claim 1 ,
wherein the runtime restriction comprises an access rights restriction and/or a limitation of an output of passed-in parameters to other software components or function calls.
10 . The method as claimed in claim 1 , further comprising:
extending the deployment information to include vulnerability information which is assigned to the identified software component and/or the at least one program component identified as having the vulnerability, wherein the vulnerability information includes a presence of a vulnerability and/or a correction of the vulnerability by the runtime restriction, and/or storing the vulnerability information, which is assigned to the identified software component and/or to the at least one program component identified as having the vulnerability, in a vulnerability database.
11 . The method as claimed in claim 1 , further comprising:
searching the deployment information for the software component for vulnerability information that is assigned to the software component and/or the identified program component; and implementing the deployment of the software component on a basis of the vulnerability information.
12 . The method as claimed in claim 10 ,
wherein the checking further comprises: storing the vulnerability information as configuration data in a vulnerability database for a vulnerability scanning process.
13 . The method as claimed in claim 1 ,
wherein a vulnerability involves a possibility of passing unchecked parameters and/or a function call by the software component.
14 . A method for operating a processing system which is configured for providing one or more software functions, wherein a plurality of cooperating software components are implemented in runtime environments, comprising:
operating one of the software components according to a method as claimed in claim 1 .
15 . A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method, as claimed in claim 1 .Join the waitlist — get patent alerts
Track US2025111035A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.